KnowBe4's Email Exposure Check Discovers Data Breach

Stu Sjouwerman | Aug 18, 2014

You are probably aware of the free one-time Email Exposure Check Pro (EEC Pro) we can run for you. We find all the email addresses of your domain that are out there available on the Internet. If we can find them, so can cybercriminals!

Recently the EEC Pro we ran for a customer discovered several of that customer's email addresses listed on a website ending with the file extension '.sql'. We inspect all suspicious EEC Pro results, and this particular result was a complete dump of that company's customer's database and to add insult to injury, it was even indexed by Google.

This information was publicly available and exposed to the Internet for several months. The information within the database included:

  1. Over 34,000 Full name, address, phone number, email, usernames, plain-text passwords and purchases made
  2. Over 200 plain-text full credit card numbers with expiration dates.

After further investigation it was determined that a portion of this data had been posted on Twitter several months prior by a known hacker group.

This is the kind of thing that the Email Exposure Check Pro may uncover for you, apart from the email addresses of your employees and on which (hacker) sites we found these addresses, which constitutes your phishing attack surface. See how it works:

Find out which of your users' emails are exposed before bad actors do.

Many of the email addresses and identities of your organization are exposed on the internet and easy to find for cybercriminals. With that email attack surface, they can launch social engineering, spear phishing and ransomware attacks on your organization. KnowBe4's Email Exposure Check Pro (EEC) identifies the at-risk users in your organization by crawling business social media information and now thousands of breach databases.

EECPro-1Here's how it works:

  • The first stage does deep web searches to find any publicly available organizational data
  • The second stage finds any users that have had their account information exposed in any of several thousand breaches
  • You will get a summary report PDF as well as a link to the full detailed report
  • Results in minutes!

Get Your Free Report

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/email-exposure-check/

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.